DPDP Act 2023 · Section 33 · Schedule of Penalties

DPDP penalties in India. Up to ₹250 crore per violation.

The Digital Personal Data Protection Act, 2023 sets financial penalties for data-protection failures through the Schedule read with Section 33. Ceilings run from ₹10,000 for data-principal misuse up to ₹250 crore for security-safeguards failure, with two ₹200 crore bands for breach-notification and children-data obligations, and a ₹150 crore band for Significant Data Fiduciary obligations. The Data Protection Board of India adjudicates each case after inquiry and can weigh mitigation. This page breaks down every band with the exact section citation, and the controls the DPB will ask for.

Section-by-section breakdown Written by DPDP practitioners Verified against DPDP Act Schedule, July 2026
DPDP Penalty Ladder
Security safeguards failure ..... ₹250 Cr
Breach notification failure ..... ₹200 Cr
Children data obligations ....... ₹200 Cr
SDF additional obligations ...... ₹150 Cr
Other DPDP obligations .......... ₹50 Cr
Data principal misuse ........... ₹10,000
Voluntary undertaking breach .... Variable
Source: Schedule to DPDP Act 2023 · Section 33
Every DPDP penalty band, decoded

The seven penalty bands under DPDP Act 2023

The DPDP Schedule assigns each type of non-compliance a maximum penalty. The Data Protection Board of India (DPB) adjudicates the actual number under Section 33, weighing gravity, duration and mitigation. Here is what each band covers.

₹250 Cr
Security safeguards failure

Failure to take reasonable security safeguards to prevent a personal data breach under Section 8(5). The single largest exposure. Applies to encryption, access control, hardening, logging, backup, incident response.

₹200 Cr
Breach notification failure

Failure to give the Data Protection Board or affected data principals notice of a personal data breach. Time-of-essence obligation, hospitals, fintechs, e-commerce especially exposed.

₹200 Cr
Children data breach

Failure to fulfil Section 9 obligations for children: verifiable parental consent, prohibition on tracking, prohibition on targeted advertising, prohibition on processing that causes detrimental effect.

₹150 Cr
SDF additional obligations

Significant Data Fiduciaries failing to appoint a DPO based in India, or to conduct DPIAs and independent audits under Section 10. Applies to most banks, NBFCs, insurance, large healthcare, and platform businesses.

Variable
Voluntary undertaking breach

Breach of a voluntary undertaking accepted by the DPB under Section 32. Under Schedule Item 6, the penalty extends to the amount applicable to the underlying contravention. So if the underlying breach carried a ₹250 Cr ceiling, breaking the undertaking exposes you to the same ₹250 Cr ceiling.

₹50 Cr
Other DPDP obligations

Catch-all for other failures, consent format, purpose limitation, retention, cross-border transfer, DSR fulfilment, notice requirements. Any obligation not called out specifically lands here.

₹10,000
Data principal misuse

A data principal filing false or frivolous grievances, or misusing rights (Section 15). Small by design, the DPDP focuses accountability on fiduciaries.

₹250 Cr
Max per violation
Per instance
Not annual, not per-org
Cumulative
Multiple violations stack
May 2027
Full enforcement deadline
DPDP Act 2023 · Schedule

Which section triggers which fine

The Schedule to the DPDP Act 2023 sets the ceiling. The DPB decides the actual figure after inquiry.

Provision breachedNature of defaultMax penalty
Section 8(5)Failure to take reasonable security safeguards to prevent a personal data breach₹250 Cr
Section 8(6) & DPDP Rules 2025 Rule 7Failure to notify DPB and affected data principals of a personal data breach₹200 Cr
Section 9Failure to fulfil additional obligations in relation to children, verifiable parental consent, no tracking, no targeted ads₹200 Cr
Section 10Failure of Significant Data Fiduciary to fulfil DPO, DPIA and audit obligations₹150 Cr
Section 32 (Schedule Item 6)Breach of a voluntary undertaking accepted by the DPB. Penalty extends to the amount applicable to the underlying contravention.Variable
Any other provisionAny other breach of the DPDP Act or Rules, consent, purpose, retention, cross-border, DSR₹50 Cr
Section 15Data principal furnishing false particulars, filing frivolous grievances, or misusing rights₹10,000
Section 33(2)

Six factors the DPB weighs before setting the fine

The DPB is not required to impose the maximum. Under Section 33(2) it must consider these mitigating and aggravating factors.

Nature and gravity of breach

How intentional or negligent was the failure. A one-off configuration error is weighed differently to a policy of ignoring data-principal rights.

Duration of breach

How long the violation continued. Six months of missing consent is weighed harder than a two-day lapse.

Impact on data principals

Number of individuals affected, category of data, whether the data was sensitive, whether harm was actually caused.

Financial gain from breach

Whether the fiduciary derived commercial benefit from the non-compliance, e.g., unlawful profiling or targeted ads.

Repetitive or recurring

A first offence weighs less than repeated failures across the same business.

Mitigation actions taken

Prompt breach notification, remediation, cooperation with DPB, prior compliance programme. This is where an audit-ready compliance stack pays off.

Real-world exposure by industry

Who bears the biggest DPDP penalty risk

Hospitals & diagnostic labs

Sensitive health data at volume. Section 8(5) + Section 10 (SDF likely) + Section 9 (paediatric consent). Combined exposure per incident: ₹600 Cr+.

See industry door
NBFCs & fintechs

RBI overlap + KYC + Aadhaar. Section 8(5) + Section 10 (SDF certain) + cross-border transfer. Combined exposure: ₹400 Cr+.

See industry door
Hotels & hospitality

Guest ID, payment data, CCTV, WiFi logs. Section 8(5) + breach notification failure + OTA data sharing without DPA.

See industry door
E-commerce & marketplaces

Buyer PII + seller PII + payment tokens + targeting cookies. Consent failure + retention creep + cross-border transfer to global CDN.

See industry door
SaaS & B2B tech

Processor role + international transfers + audit-readiness. Vendor DPA failure + SDF classification if scale is large.

See industry door
EdTech & schools

Under-18 users almost universally. Section 9 exposure of ₹200 Cr on tracking or targeted ads alone.

See industry door
Reduce your DPDP penalty exposure

The eight controls the DPB will ask you to prove

Section 33(2)(f) rewards documented mitigation. Every one of these has a dcomply module.

Consent artefacts

Free, informed, specific, unambiguous, withdrawable. Versioned, timestamped, exportable.

See module
Record of Processing Activities (RoPA)

Every purpose, every category, every retention rule. The first thing the DPB will ask for.

See module
DSR fulfilment log

Every access, correction and erasure request with SLA clock. Section 12 evidence.

See module
Breach notification workflow

DPB format + affected data principal notice. 72-hour ready. Section 8(6).

See module
DPIA library

Section 10(2)(c) obligation for SDFs. dcomply auto-triggers on high-risk processing.

See module
DPO appointment

Section 10 for SDFs. dcomply vDPO fulfils this from ₹2,499/month.

See module
Vendor DPA library

Every processor covered by a signed DPA. Section 8(2) obligation.

See module
Independent audit trail

Section 10(2)(c) audit obligation. Evidence Locker keeps every artefact hash-chained.

See module
DPDP penalty FAQs

The exact questions general counsel asks about DPDP fines.

The maximum penalty under the DPDP Act 2023 is ₹250 crore per instance of non-compliance. This applies to failure to implement reasonable security safeguards under Section 8(5). The penalty is imposed by the Data Protection Board of India after inquiry and adjudication under Section 33.

It is per instance of non-compliance, not annual. Multiple violations arising from the same incident can attract cumulative penalties. The DPB is required to consider mitigating and aggravating factors under Section 33(2), nature, gravity, duration, impact on data principals, gains from the breach, and mitigation actions taken.

Failure to notify a personal data breach to the Data Protection Board and to affected data principals carries a penalty up to ₹200 crore under the Schedule to the DPDP Act. This is separate from and additional to the security-safeguards penalty.

Failure to fulfil additional obligations in relation to children under Section 9, including obtaining verifiable parental consent, prohibitions on tracking and targeted advertising, and prohibitions on processing that causes detrimental effects, carries a penalty up to ₹200 crore.

SDFs that fail to appoint a DPO, complete DPIAs or engage independent auditors under Section 10 face penalties up to ₹150 crore. Most banks, NBFCs, insurance companies, large e-commerce and healthcare providers will be classified as SDFs.

Yes. Data principals who file false or frivolous grievances, or misuse their rights, may face a penalty up to ₹10,000 under the Schedule. This is deliberately modest, reflecting the DPDP's focus on holding fiduciaries accountable.

The Data Protection Board of India (DPB) imposes penalties after adjudication under Section 33. The DPB may accept voluntary undertakings under Section 32 in lieu of penalty. If the person subsequently breaches the undertaking, Schedule Item 6 says the penalty extends to the amount applicable to the underlying contravention, so if the original breach was a security-safeguards failure the exposure is still ₹250 crore. Penalties are recoverable as arrears of land revenue.

DPDP penalties are civil, not criminal. The Act does not create imprisonment offences. However, criminal liability under other laws (IT Act, IPC, sectoral regulations like RBI, IRDAI) may still apply to the same conduct.

Yes. Appeals from DPB orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Appeal must be filed within 60 days. The Supreme Court sits above TDSAT on questions of law.

Under Section 33(2) the DPB weighs mitigation actions taken. Concretely: maintain an evidence-backed compliance programme (RoPA, DPIA, consent records, DSR fulfilment logs), respond promptly to breaches, appoint a DPO where required, run periodic audits, and produce documented remediation. dcomply is designed to give you the audit trail the DPB will ask for.

Don't wait for the DPB to knock.

Get a free 5-minute DPDP readiness score. Know exactly which of the seven penalty bands you're exposed to today.